Re: The Kernal Is A Huge Security Whole In Windows

From: Miha Pihler (miha-news_at_atlantis.si)
Date: 07/17/04


Date: Sat, 17 Jul 2004 19:03:06 +0200

I see you haven't looked at this posted in one of my previous posts.

Description of the Windows File Protection Feature
http://support.microsoft.com/default.aspx?scid=kb;EN-US;222193

In this article it is explained:

If WFP finds the file in the cache folder or if the installation source is
automatically located, WFP silently replaces the file. If WFP cannot
automatically find the file in any of these locations, you receive one of
the following messages, where file_name is the name of the file that was
replaced and product is the Windows product you are using:

Windows File Protection
Files that are required for Windows to run properly have been replaced by
unrecognized versions. To maintain system stability, Windows must restore
the original versions of these files. Insert your product CD-ROM now.
This means that if the virus is to replace a system file in e.g.
%systemroot%\system32 folder AND in %systemroot%\system32\dllcache folder at
the same time, operating system will demand from you to insert a CD with
original installation and replaced files are copied from there. Yes, if you
inserted a CD that doesn't have SP4 applied to it you will have to apply SP4
manually... You can then also use MBSA to scan for any other critical
patches that need to be applied... MBSA actually looks for version of .dll
file that must exist on system - it doesn't look only for existing registry
keys.

Mike

"CHANGE USERNAME TO westes" <DELETE_westes@earthbroadcast.com> wrote in
message news:ukvKpS1aEHA.3988@tk2msftngp13.phx.gbl...
>
> "Roger Abell" <mvpNOSpam@asu.edu> wrote in message
> news:uWH51PuaEHA.3356@tk2msftngp13.phx.gbl...
> > Between SFC and use of signed driver requirements you
> > can start to feel you have tightened the type of exploit path
> > you have been outlining.
>
> By the way, I'm still not clear on this: when I enable SFC, it seems to
> want to populate the dllcache with files from the original CD. How can
it
> rely on these when the system may already be running a very late SP with
> lots of minor patches as well? Does Windows Update automatically keep
> the dllcache up to date?
>
> Wouldn't a virus defeat this just by writing itself to both the cache and
> system32 directories?
>
>
> > But think about it. Some driver is say causing issues - like your
> > 100% cpu use. If blind, prefabricated statistics were shown of
> > the different kernel "parts", you might see that driver getting very
> > small %age of cpu, but some valid and errorfree part of kernel
> > consuming high amount of cycles - not because it is in error but
> > because it is being driven by something that is in error. With
> > debugger you see the call stack and what is driving what how.
>
> That's obviously an excellent point. So it suggests to me that a
> diagnostic tool for the kernel, if it is to be used by relatively junior
> system administrators, must have the ability to show who are the primary
> users of different shared components. It must be possible for Microsoft
> to do this, but first they have to believe there is a requirement for it
in
> the first place.
>
> It's depressing to me that someone in our company won't be able to do
their
> job for a week, while their whole user environment is reconstructed from
> scratch, because we cannot do any diagnosis on what is wrong with their
> system.
>
> --
> Will
> westes AT earthbroadcast.com
>
>



Relevant Pages

  • Re: scan for file corruption
    ... Windows XP has the ability to protect itself from system instability caused by ... Windows File Protection is always enabled and allows Windows ... see if there are any corrupt system files using scannow sfc. ... NB - The dllcache folder is extremely important so Windows XP hides it from ...
    (microsoft.public.windowsxp.newusers)
  • Re: Problem with print services for Unix
    ... Window File Protection prevents programs from replacing critical Windows ... WFP uses the file signatures and catalog files that are generated by code ... How to Disable Windows File Protection in Windows 2000 ...
    (microsoft.public.windows.server.setup)
  • Re: My Time-Zone resets itself...?
    ... You downloaded and installed Windows XP SP2 from the Microsoft Web site. ... Description of Windows XP and Windows Server 2003 System File Checker ... HOW TO Verify That Windows File Protection Is Running ... In the off chance that w32time.dll (Windows Time Service) is messed up, ...
    (microsoft.public.windowsxp.general)
  • Re: Please advise regarding virus problem
    ... I observed that I already have a i386 folder on ... | The error code references Windows 2000 and Windows XP Media Edition, ... | and then click Cancel every time that you receive an error message. ... | Drag the Windows File Protection dialog box to another location on the ...
    (microsoft.public.windowsxp.security_admin)
  • Re: system file checker
    ... Specifies the maximum disk space that the Windows File Protection file cache can use. ... Since you do not have the %windir%\ServicePackFiles folder, ... Try changing ServicePackSourcePath to C:\ ...
    (microsoft.public.windowsxp.help_and_support)